The company behind The War for the Mind introduces a new kind of security system: a deliberative AI security organization that analyzes threats, challenges its own conclusions, and shows its work.
NEW YORK — POINT today announced the formation of a security technology company built around a proposition the industry has largely avoided:
The next great security problem is not simply detecting what happened. It is understanding what is happening.
POINT is developing a white-box, AI-native security platform designed to operate alongside existing security infrastructure rather than replace it.
Firewalls remain.
Email gateways remain.
Endpoint detection remains.
Identity systems remain.
SIEMs remain.
POINT sits above them.
It is the reasoning layer.
⸻
SECURITY HAS BECOME AN INTERPRETATION PROBLEM
For decades, security products have become increasingly effective at collecting evidence.
They generate logs.
They correlate events.
They assign severity.
They block connections.
They quarantine messages.
They isolate endpoints.
But the modern attacker increasingly understands the same thing security engineers understand:
The easiest system to compromise may be the human being interpreting the evidence.
A convincing email.
A legitimate credential.
A plausible business request.
A compromised account behaving almost normally.
A real event wrapped in a false explanation.
The question is no longer merely:
“Is this malicious?”
It is:
“Why do we believe that?”
POINT was built around that question.
⸻
A SECURITY TEAM MADE OF SOFTWARE
POINT uses a deliberately divided architecture.
Specialized AI analysts examine different classes of evidence while operating under constrained permissions.
A mail analyst examines mail-flow evidence.
An identity analyst examines authentication behavior.
A network analyst examines network telemetry.
A DNS analyst examines domain infrastructure.
An endpoint analyst examines host behavior.
Additional analysts can be deployed for cloud infrastructure, vulnerability intelligence, fraud, insider-risk signals, application security, or other domains.
They do not all receive unrestricted access.
They report to a supervisory reasoning system.
And before POINT accepts a significant conclusion, another system is explicitly assigned to challenge it.
The Counter-Analyst.
Its job is simple:
Prove us wrong.
⸻
POINT DOES NOT HIDE UNCERTAINTY
A conventional security dashboard might tell an analyst:
HIGH SEVERITY — TAKE ACTION
POINT instead attempts to expose the reasoning underneath the recommendation.
What happened?
What evidence supports that conclusion?
What alternative explanations exist?
What evidence contradicts it?
What information is missing?
What would change the assessment?
What is the safest next action?
The objective is not to manufacture certainty.
The objective is to make uncertainty useful.
⸻
THE POINT DASHBOARD
A POINT installation is designed to turn thousands of individual observations into a smaller number of understandable situations.
Instead of presenting an endless wall of alerts, POINT can organize related evidence into an investigation:
SITUATION
Suspicious administrative authentication
Evidence:
Identity telemetry, DNS activity, endpoint events
Assessment:
Potential credential compromise
Alternative explanation:
Authorized remote administration
Missing evidence:
VPN session correlation
Recommended action:
Verify the administrator session
Easy remediation:
Rotate credentials if unauthorized activity is confirmed
External intelligence:
Relevant activity reported by current threat sources
Confidence:
Moderate
The analyst is not asked to trust the machine.
The analyst is given enough information to question it.
⸻
A GLOBAL INTELLIGENCE LAYER
POINT also incorporates continuously changing external information.
Security advisories.
Threat intelligence.
Research.
Vulnerability disclosures.
Corporate announcements.
Geopolitical developments.
Incident reporting.
Public technical documentation.
The system asks a deceptively simple question:
“Does anything happening in the world change the meaning of what we’re seeing here?”
That question turns a static security appliance into a continuously updating intelligence system.
⸻
WHITE-BOX BY DESIGN
POINT is being designed as a deployable white-box platform.
Customers and security integrators can operate it inside their own environments and connect it to the security products they already own.
The architecture is intended to support local models, customer-selected models, configurable analytical agents, auditable prompts and policies, and controlled access to customer data.
POINT is not asking organizations to throw away their security investments.
It is asking them to give those investments something they have historically lacked:
a deliberative layer.
⸻
BUILT FOR THE PEOPLE WHO ALREADY SELL SECURITY
POINT is intended to be distributed through security integrators and technology partners.
The partner does not have to explain a new security category to every customer.
The pitch is straightforward:
Your existing security products collect the evidence. POINT helps you understand it.
A Proofpoint deployment can feed POINT.
A Check Point deployment can feed POINT.
An endpoint platform can feed POINT.
An identity platform can feed POINT.
A SIEM can feed POINT.
The customer keeps the infrastructure.
POINT adds the reasoning.
⸻
THE COMPANY BEHIND THE MACHINE
POINT was founded on an idea stated in the company’s first public editorial, The War for the Mind:
The next great security battle may not be fought over access to information. It may be fought over the interpretation of information.
The company therefore rejects a simple model of artificial intelligence in which one enormous model becomes the unquestioned authority.
POINT’s architecture is deliberately argumentative.
Multiple analysts.
Separated privileges.
Independent evidence.
Competing interpretations.
A supervisory system.
A Counter-Analyst.
Human review.
Auditable conclusions.
The objective is not an AI that always agrees with its operator.
It is an AI that can explain why it disagrees.
⸻
THE POINT PRINCIPLE
There is an old assumption in security:
Trust, but verify.
POINT proposes something more demanding:
Understand, then decide.
Because when machines become capable of reasoning across millions of events, the human problem changes.
We will not merely need machines that can find threats.
We will need machines that can explain the evidence.
Machines that can challenge themselves.
Machines that can distinguish facts from interpretations.
Machines that can tell us what they don’t know.
And machines that can show us exactly why they reached a conclusion.
That is POINT.
Not another security product.
A security organization in software.
POINT
Make the machine show its work.
Facts Only
* POINT announced the formation of a security technology company.
* The new focus is on understanding security events rather than just detection.
* POINT develops a white-box, AI-native security platform.
* It is designed to operate alongside existing infrastructure.
* Existing security products like firewalls, email gateways, and SIEMs remain operational.
* POINT functions as a reasoning layer above existing systems.
* POINT uses a divided architecture with specialized AI analysts (mail, identity, network, endpoint, etc.).
* A Counter-Analyst system is included to challenge conclusions.
* The system aims to expose uncertainty rather than manufacture certainty.
* POINT incorporates external intelligence such as threat advisories and geopolitical developments.
Executive Summary
Full Take
Sentinel — Human
The text reads as a well-articulated, intentionally structured argument for a novel approach to AI in security, exhibiting strong human authorship focused on philosophical and architectural positioning rather than mere description.
